fix(connect): default Basic-auth username to 'opencode' when password set (critical)

Quick Connect (the DEFAULT add-connection mode) has no username field, so every
auth-build site (username && password ? {..} : undefined) produced undefined auth
whenever a password was set but username empty -> NO Authorization header -> 401
against a password-protected server. This is the common setup
(OPENCODE_SERVER_PASSWORD=... opencode serve) and a top install->churn cause:
user sets a password, can't connect, gives up.

Fix: extract buildAuth() to a pure, testable module; when a password is present but
username is empty, default username to 'opencode' (the server's own default,
OPENCODE_SERVER_USERNAME ?? 'opencode'). Advanced mode's explicit username is
preserved. Replaced all 6 inline ternaries in connections.ts.

+3 regression tests (68 total pass), typecheck clean. Found while setting up an
on-device emulator test of the connect flow.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
engineer
2026-06-08 07:50:19 -07:00
parent e39cec3847
commit 4b21ed73c2
3 changed files with 51 additions and 6 deletions

22
src/lib/auth.test.ts Normal file
View File

@@ -0,0 +1,22 @@
import { test } from "node:test"
import assert from "node:assert/strict"
import { buildAuth } from "./auth.ts"
test("no password -> no auth (open server)", () => {
assert.equal(buildAuth("opencode", undefined), undefined)
assert.equal(buildAuth("opencode", null), undefined)
assert.equal(buildAuth("opencode", ""), undefined)
})
test("password but no username -> defaults username to 'opencode' (Quick Connect fix)", () => {
// Regression guard: Quick Connect has no username field. Before the fix, an empty
// username made auth undefined and the app sent NO Authorization header -> 401.
assert.deepEqual(buildAuth(undefined, "secret"), { username: "opencode", password: "secret" })
assert.deepEqual(buildAuth("", "secret"), { username: "opencode", password: "secret" })
assert.deepEqual(buildAuth(" ", "secret"), { username: "opencode", password: "secret" })
})
test("explicit username preserved (Advanced mode), trimmed", () => {
assert.deepEqual(buildAuth("alice", "secret"), { username: "alice", password: "secret" })
assert.deepEqual(buildAuth(" alice ", "secret"), { username: "alice", password: "secret" })
})

22
src/lib/auth.ts Normal file
View File

@@ -0,0 +1,22 @@
// Pure Basic-auth credential construction for opencode connections.
// Extracted from stores/connections.ts so the username-defaulting rule is unit-testable
// without pulling in zustand/expo (which have no resolver outside Metro).
export interface BasicAuth {
username: string
password: string
}
// The opencode server's default Basic-auth username is "opencode"
// (OPENCODE_SERVER_USERNAME ?? "opencode"). Quick Connect collects only a password
// (it has no username field), so when a password is set but no username, default the
// username to "opencode". Without this, an empty username made auth undefined entirely —
// no Authorization header was sent — and a password-protected server returned 401,
// i.e. the common "I set a password and now it won't connect" failure.
export function buildAuth(
username: string | null | undefined,
password: string | null | undefined,
): BasicAuth | undefined {
if (!password) return undefined
return { username: username?.trim() || "opencode", password }
}